Audit log¶
The audit log answers "who changed this, and when?" for your whole account: changes made in the web portal, and sign-ins, PIN checks and commands at your on-site panels and WhiskerHMI PCs. Open it at Control Panel → Audit Log.
Note
The Audit Log tab is shown only to people in the View Audit Log role and to Account Admins (see Roles and permissions).
What is recorded¶
Only changes and security events are recorded. Looking at a page is not.
Recorded events include:
- Sign-in and security: sign-ins and failed sign-ins at panels and PCs, PIN checks, PINs locked after too many attempts, sessions locked or timed out.
- Equipment: commands, setpoint and mode changes sent from an HMI; device and gateway changes.
- HMI design: HMIs created, edited or deleted; widgets added, edited or removed; background images and HMI roles changed.
- Alerts: alerts created or edited; contacts added, edited or removed; schedule changes; alerts acknowledged or snoozed, and snoozes cancelled.
- Account and people: account details, account role assignments, location roles, the HMI PIN policy, users created or edited, role memberships, password and PIN changes, PIN resets, roles created or renamed.
- Locations, dashboards and reports: created, edited or deleted.
Every entry also records attempts that were refused because the person didn't hold the required role, so you can see who tried to do something they weren't allowed to.
Find events¶
The filters are at the top of the tab. Choose them, then click Apply.
| Filter | Options |
|---|---|
| Range | Today, Last 24 hours, Last 7 days (the default), Last 30 days, or Custom… with From and To dates |
| User | One person, or Any user |
| Source | Where it happened: All panels, All PCs, Portal / cloud, or one panel or PC |
| Action | One kind of event, or a whole group (for example user · (all)) |
| Result | OK, Denied or Failed |
| Search | Text in the target, the value or the reason. Press Enter to apply |
| Denied only | Only refused attempts |
| Security events only | Only sign-in, PIN and other security events |
Above the grid, a summary shows how many events, users, denied attempts and reporting sources the current filter covers.
Read the grid¶
| Column | Contents |
|---|---|
| When | Date and time in your browser's time zone. Hover for the UTC time |
| Who | The person, with a tag for how they were identified: Password, PIN, Offline PIN, API key, Kiosk, System or Portal. Nobody logged in means a panel in kiosk mode |
| Where | The panel, PC or portal the event came from |
| Action | What happened, for example Changed setpoint or Reset PIN |
| Target | What it was done to |
| Change | The old and new value, as old → new |
| Result | OK (green), Denied (red) or Failed (orange). Hover for the reason |
| Location / Device | The location, device and screen involved |
The newest events are first. Click a column heading to sort, and use the pager at the bottom to see 50, 100 or 250 rows at a time. Click the arrow at the start of a row to see its full details.
Note
A red chain gap label means records from a panel or PC arrived out of sequence, so an event may be missing. If you see one, contact D6 Labs support.
Export¶
Click Export CSV to download the events that match the current filters as a spreadsheet file, for example for compliance records. Exporting is itself recorded in the audit log.
The location History tab¶
Each location also has a History tab, which lists activity at that location only. See Locations and HMIs. Use the audit log for account-wide changes, for panel and PC events, and for refused attempts.